forked from iovisor/bcc
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Ringbuf Support for Python API (iovisor#2989)
This pull request contains an implementation for ringbuf support in bcc's Python API. Fixes iovisor#2985. More specifically, the following are added: - ringbuf helpers from libbpf API to libbcc - a new RingBuf class to represent the ringbuf map - BPF_RINGBUF_OUTPUT macro for BPF programs - tests - detailed documentation and examples
- Loading branch information
1 parent
156a7d1
commit fe730f2
Showing
12 changed files
with
837 additions
and
62 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,53 @@ | ||
#!/usr/bin/python3 | ||
|
||
import sys | ||
import time | ||
|
||
from bcc import BPF | ||
|
||
src = r""" | ||
BPF_RINGBUF_OUTPUT(buffer, 1 << 4); | ||
struct event { | ||
char filename[16]; | ||
int dfd; | ||
int flags; | ||
int mode; | ||
}; | ||
TRACEPOINT_PROBE(syscalls, sys_enter_openat) { | ||
int zero = 0; | ||
struct event event = {}; | ||
bpf_probe_read_user_str(event.filename, sizeof(event.filename), args->filename); | ||
event.dfd = args->dfd; | ||
event.flags = args->flags; | ||
event.mode = args->mode; | ||
buffer.ringbuf_output(&event, sizeof(event), 0); | ||
return 0; | ||
} | ||
""" | ||
|
||
b = BPF(text=src) | ||
|
||
def callback(ctx, data, size): | ||
event = b['buffer'].event(data) | ||
print("%-16s %10d %10d %10d" % (event.filename.decode('utf-8'), event.dfd, event.flags, event.mode)) | ||
|
||
b['buffer'].open_ring_buffer(callback) | ||
|
||
print("Printing openat() calls, ctrl-c to exit.") | ||
|
||
print("%-16s %10s %10s %10s" % ("FILENAME", "DIR_FD", "FLAGS", "MODE")) | ||
|
||
try: | ||
while 1: | ||
b.ring_buffer_poll() | ||
# or b.ring_buffer_consume() | ||
time.sleep(0.5) | ||
except KeyboardInterrupt: | ||
sys.exit() |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,56 @@ | ||
#!/usr/bin/python3 | ||
|
||
import sys | ||
import time | ||
|
||
from bcc import BPF | ||
|
||
src = r""" | ||
BPF_RINGBUF_OUTPUT(buffer, 1 << 4); | ||
struct event { | ||
char filename[64]; | ||
int dfd; | ||
int flags; | ||
int mode; | ||
}; | ||
TRACEPOINT_PROBE(syscalls, sys_enter_openat) { | ||
int zero = 0; | ||
struct event *event = buffer.ringbuf_reserve(sizeof(struct event)); | ||
if (!event) { | ||
return 1; | ||
} | ||
bpf_probe_read_user_str(event->filename, sizeof(event->filename), args->filename); | ||
event->dfd = args->dfd; | ||
event->flags = args->flags; | ||
event->mode = args->mode; | ||
buffer.ringbuf_submit(event, 0); | ||
// or, to discard: buffer.ringbuf_discard(event, 0); | ||
return 0; | ||
} | ||
""" | ||
|
||
b = BPF(text=src) | ||
|
||
def callback(ctx, data, size): | ||
event = b['buffer'].event(data) | ||
print("%-64s %10d %10d %10d" % (event.filename.decode('utf-8'), event.dfd, event.flags, event.mode)) | ||
|
||
b['buffer'].open_ring_buffer(callback) | ||
|
||
print("Printing openat() calls, ctrl-c to exit.") | ||
|
||
print("%-64s %10s %10s %10s" % ("FILENAME", "DIR_FD", "FLAGS", "MODE")) | ||
|
||
try: | ||
while 1: | ||
b.ring_buffer_consume() | ||
time.sleep(0.5) | ||
except KeyboardInterrupt: | ||
sys.exit() |
Oops, something went wrong.